VDE
Products
3- 47 CVEs
- 1 CVE
- 0 CVEs
Recent CVEs
48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6596 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | ||
| CVE-2024-6422 | Cri | 0.64 | 9.8 | 0.01 | Jul 10, 2024 | An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data. | ||
| CVE-2024-25995 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2024 | An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. | ||
| CVE-2023-4149 | Cri | 0.64 | 9.8 | 0.01 | Nov 21, 2023 | A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based… | ||
| CVE-2022-45140 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise. | ||
| CVE-2022-45138 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2023 | The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full… | ||
| CVE-2024-28751 | Cri | 0.59 | 9.1 | 0.01 | Jul 9, 2024 | An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. | ||
| CVE-2024-7699 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data. | ||
| CVE-2024-43388 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. | ||
| CVE-2015-10123 | Hig | 0.57 | 8.8 | 0.01 | Mar 13, 2024 | An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device. | ||
| CVE-2024-26288 | Hig | 0.57 | 8.7 | 0.00 | Mar 12, 2024 | An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected. | ||
| CVE-2023-6357 | Hig | 0.57 | 8.8 | 0.01 | Dec 5, 2023 | A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | ||
| CVE-2024-25999 | Hig | 0.55 | 8.4 | 0.00 | Mar 12, 2024 | An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. | ||
| CVE-2025-41654 | Hig | 0.53 | 8.2 | 0.00 | May 26, 2025 | An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog. | ||
| CVE-2024-41973 | Hig | 0.53 | 8.1 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges. | ||
| CVE-2024-41971 | Hig | 0.53 | 8.1 | 0.01 | Nov 18, 2024 | A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss. | ||
| CVE-2024-41967 | Hig | 0.53 | 8.1 | 0.00 | Nov 18, 2024 | A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack. | ||
| CVE-2024-28136 | Hig | 0.51 | 7.8 | 0.01 | May 14, 2024 | A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service. | ||
| CVE-2023-49675 | Hig | 0.51 | 7.8 | 0.00 | May 6, 2024 | An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability. | ||
| CVE-2025-41689 | Hig | 0.49 | 7.5 | 0.00 | Aug 19, 2025 | An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data. |
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can manipulate the device via Telnet, stop processes, read, delete and change data.
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.
- risk 0.64cvss 9.8epss 0.01
A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based…
- risk 0.64cvss 9.8epss 0.01
The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.
- risk 0.64cvss 9.8epss 0.01
The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…
- risk 0.59cvss 9.1epss 0.01
An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.
- risk 0.57cvss 8.8epss 0.01
An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
- risk 0.57cvss 8.8epss 0.01
An unautheticated remote attacker could send specifically crafted packets to a affected device. If an authenticated user then views that data in a specific page of the web-based management a buffer overflow will be triggered to gain full access of the device.
- risk 0.57cvss 8.7epss 0.00
An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.
- risk 0.57cvss 8.8epss 0.01
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
- risk 0.55cvss 8.4epss 0.00
An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service.
- risk 0.53cvss 8.2epss 0.00
An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of returned data can trigger a reboot by the watchdog.
- risk 0.53cvss 8.1epss 0.01
A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.
- risk 0.53cvss 8.1epss 0.01
A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.
- risk 0.53cvss 8.1epss 0.00
A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.
- risk 0.51cvss 7.8epss 0.01
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
- risk 0.51cvss 7.8epss 0.00
An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds write vulnerability.
- risk 0.49cvss 7.5epss 0.00
An unauthenticated remote attacker can get access without password protection to the affected device. This enables the unprotected read-only access to the stored measurement data.